US2015371234A1PendingUtilityA1

Methods, devices, and systems for secure provisioning, transmission, and authentication of payment data

Assignee: LOOPPAY INCPriority: Feb 21, 2014Filed: Oct 10, 2014Published: Dec 24, 2015
Est. expiryFeb 21, 2034(~7.6 yrs left)· nominal 20-yr term from priority
G06Q 20/327G06Q 20/40G06Q 20/34G06Q 20/20G06Q 20/363G06Q 20/3823G06Q 20/409G06Q 20/382G06Q 20/36G06Q 20/40975G06Q 20/4018G06Q 20/385
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Devices, systems, and methods for securely converting a user's existing static payment card data into dynamic card data that can be authenticated by card issuers or by a stand-in service provider, such as a payment network or processor without requiring the card issuers to make infrastructure changes. The dynamic data can be provisioned onto a magnetic secure transmission device (MST) either directly from a card issuer or using a swiper type device. Devices, systems, and methods are also disclosed for securely provisioning a dynamic card onto the MST by the card issuer. These dynamic cards may be used to transmit modified one-time-use card track data from the MST to a point of sale using a dynamic-CVV methodology to provide higher levels of security during a transaction.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for creating dynamic card data, comprising:
 receiving, by a device, card track data;   encrypting, by the device, the card track data using a first key;   sending, by the device, the encrypted card track data to a server;   receiving, by the device, a working key;   generating, by the device, modified card track data including a time-dependent CVV using the working key; and   sending, by the device, the modified card track data to a point of sale terminal or causing the modified card track data to be displayed to a user for use in an e-commerce transaction.   
     
     
         2 . The method of  claim 1 , wherein an expiration date, a registered primary account number, or a portion of a discretionary field of the modified track data indicates to a card issuer or a third party service provider that the modified card track data is dynamic-CVV (dCVV) card track data and authorization is to be performed in a dCVV mode. 
     
     
         3 . The method of  claim 1 , wherein the sending the modified card track data to the point of sale terminal includes sending the time-dependent CVV, and a dynamic mode indicator. 
     
     
         4 . The method of  claim 3 , wherein the dynamic mode indicator is a primary account number, an expiration date, or a separate dynamic mode indicator of the modified track data. 
     
     
         5 . The method of  claim 4 , wherein the dynamic mode indicator indicates to a card issuer or third party service provider, that the modified card track data is dynamic-CVV (dCVV) card track data and authorization is to be performed in a dCVV mode. 
     
     
         6 . The method of  claim 1 , wherein the device is a magnetic stripe storage and transmission device or a mobile communication device. 
     
     
         7 . A method for provisioning dynamic financial card data by issuer, comprising:
 receiving, by a server, a request for provisioning card track data;   requesting, by the server, an authentication of a user corresponding to the card track data from a card issuer server, wherein the card issuer server corresponds to a card issuer of the card track data;   receiving, by the server, an authentication result from the card issuer server; and   generating, by the server, a working key for the generation of dynamic card track data.   
     
     
         8 . The method of  claim 7 , wherein the requesting the authentication of the user from the card issuer server includes sending a primary account number and at least one of a CVV-2, a name, a date of birth, a username and password, and an answer to a challenge question to the card issuer server for authentication. 
     
     
         9 . The method of  claim 7 , further comprising securely sending the working key to a wallet server. 
     
     
         10 . The method of  claim 7 , further comprising receiving a request for verification of a dynamic-CVV (dCVV) in response to initiation of a payment transaction, wherein the dCVV is based on the working key. 
     
     
         11 . The method of  claim 10 , wherein the receiving the request for verification of the dCVV includes receiving a primary account number, an expiration date, a service code, a time-stamp, and a mode indicator. 
     
     
         12 . The method of  claim 11 , further comprising comparing the received time-stamp with a stored time-stamp or current time on the server for verifying a transaction. 
     
     
         13 . The method of  claim 12 , further comprising sending an authorization failure in response to the stored time-stamp or current time corresponding to a time greater than the received time-stamp. 
     
     
         14 . A method for performing dynamic-CVV (dCVV), comprising:
 generating, by a server, a working key for card track data;   receiving, by a magnetic stripe storage and transmission device (MST), the working key;   generating, by the MST, modified card track data including a dCVV component based on original card track data, a time-stamp or counter and the working key;   sending the modified card track data to a point of sale terminal or e-commerce website for payment processing;   receiving, by the server, a request for verification of the dCVV from a card issuer server or a third party service provider in response to initiation of the payment processing, wherein the request includes the modified card track data;   performing, by the server, a verification of the dCVV component; and   sending, by the server, a verification failure or final verification based on the verification of the dCVV component.   
     
     
         15 . The method of  claim 14 , wherein the modified card track data includes the dCVV component, a primary account number, an expiration date, a service code, the time-stamp or counter, and optionally a separate mode indicator when the expiry date or the primary account number is not used to indicate that authorization is to be performed in a dCVV mode. 
     
     
         16 . The method of  claim 15 , wherein the mode indicator indicates to the card issuer server that the modified card track data is dCVV card track data and authorization is to be performed in a dCVV mode. 
     
     
         17 . The method of  claim 15 , wherein the performing the verification includes comparing a received time-stamp or received counter with a stored time-stamp or a current time of the server or stored counter. 
     
     
         18 . The method of  claim 17 , wherein the sending the verification failure or final verification includes sending the verification failure in response to the stored time-stamp or current time of the server corresponding to a time greater than the received time-stamp. 
     
     
         19 . The method of  claim 15 , wherein the performing the verification includes:
 independently computing, by the server, a dCVV vale using the working key; and   comparing the computed dCVV value with the dCVV component.   
     
     
         20 . The method of  claim 19 , wherein the sending the verification failure or final verification includes sending the final verification in response to the computed dCVV value matching the received dCVV component. 
     
     
         21 . The method of  claim 14 , further comprising sending, by the server, the original card track data to the card issuer server for processing via the card issuer server's normal processing methods to complete a transaction, wherein the original card track data corresponds to data of a card issuer corresponding to the card issuer server.

Join the waitlist — get patent alerts

Track US2015371234A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.